SecurityX CAS-005 network architecture objectives emphasize limiting exposure of vulnerable systems by using application-aware firewalls with strict rule sets. This approach directly reduces the attack surface by allowing only approved application traffic to and from the vulnerable systems, mitigating risk until systems are patched or replaced. EDR (A) enhances detection but doesn't inherently reduce the exposed services. Network segmentation in monitor mode (B) doesn't block threats. IDS (C) detects activity but does not block it.